pushsecurity / saas-attacks

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
https://pushsecurity.com/blog/saas-attack-techniques/
Creative Commons Attribution 4.0 International
1.16k stars 79 forks source link

Add session theft as a technique #70

Closed jukelennings closed 3 months ago

jukelennings commented 3 months ago

We are increasingly seeing hybrid attacks involving sessions stolen from different sources (e.g. dumped from cookies on compromised endpoints) being used to move laterally into the SaaS world.

This should probably be technique of its own for lateral movement and perhaps defense evasion.